Vulnerability record · CVE-2012-1457 · published 21 March 2012
CVE-2012-1457: Antivirus TAR parser malware detection bypass via oversized length field
Aladdin · Esafe
The TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size, allowing malware to evade detection. Because the flaw affects the scanning engine itself, a malicious archive can pass through the very control meant to catch it. The record notes it may later be split into multiple CVEs if the error is shown to occur independently across parsers.
Description
The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, G Data AntiVirus 21, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, Antimalware Engine 1.1.6402.0 in Microsoft Security Essentials 2.0, NOD32 Antivirus 5795, Norman Antivirus 6.06.12, PC Tools AntiVirus 7.0.3.5, Rising Antivirus 22.83.00.03, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Trend Micro AntiVirus 9.120.0.1004, Trend Micro HouseCall 9.120.0.1004, VBA32 3.12.14.2, and VirusBuster 13.6.151.0 allows remote attackers to bypass malware detection via a TAR archive entry with a length field that exceeds the total TAR file size. NOTE: this may later be SPLIT into multiple CVEs if additional information is published showing that the error occurred independently in different TAR parser implementations.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 base score is 4.3 (medium) with only integrity impact, but the flaw defeats malware detection across many widely deployed scanners and EPSS is extremely high.
What it is
The TAR file parser in numerous antivirus and anti-malware products mishandles a TAR archive entry whose length field exceeds the total TAR file size, allowing malware to evade detection. Because the flaw affects the scanning engine itself, a malicious archive can pass through the very control meant to catch it. The record notes it may later be split into multiple CVEs if the error is shown to occur independently across parsers.
Impact
An attacker gains the ability to deliver malware inside a crafted TAR archive that the affected scanner fails to flag, undermining the primary detection control. There is no reported confidentiality or availability impact; the effect is a bypass of malware detection.
Attack surface
Reached remotely over the network by submitting a crafted TAR archive to a system whose antivirus or anti-malware engine parses it. No authentication is required, but the CVSS vector indicates medium attack complexity and no user interaction is specified.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.98331, 99.9th percentile), but the references carry no exploit tags, so active exploitation is not confirmed by this record.
What to do
- Apply vendor updates for the affected antivirus/anti-malware engines; the record does not list fixed versions, so confirm with each vendor.
- Where no fix is available, disable or restrict automatic scanning of untrusted TAR archives at the gateway and endpoint.
- Block or quarantine inbound TAR archives at mail and web gateways until engines are confirmed patched.
- Layer a second detection engine or sandbox that does not share the same TAR parser implementation.
- Track the note that this CVE may be split; monitor vendor advisories for per-product identifiers and patches.
Detection
- Hunt for TAR archives where an entry's declared length field exceeds the total file size.
- Alert on TAR files passing through mail/web gateways that are subsequently executed or extracted on endpoints.
- Correlate endpoint AV logs showing archives scanned without detection against later malware execution from the same file.
- Monitor vendor advisories and engine version inventories to identify unpatched TAR parsers in the environment.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-1457 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-1457), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.